Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
juli
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
juli
17y ago
Attacker controls the length of the message so he can make the padding be only 9 bytes long
2.
▲
by
juli
17y ago
Sites using this vulnerable signing method must add a warning to their documentation. Flickr authentication spec lists ludicorp.com authors, http://www.flickr.com/services/api/auth.spec.html
3.
▲
by
juli
17y ago
MD5 is not the problem here, SHA1 is also vulnerable to the extension attack. They should use HMAC.